首页> 外文会议>IEEE GCC Conference and Exhibition >A delay-based probing technique for the discovery of a firewall's accept rules
【24h】

A delay-based probing technique for the discovery of a firewall's accept rules

机译:一种基于延迟的探测技术,用于发现防火墙接受规则

获取原文

摘要

Firewalls are widely used nowadays to protect networks, and they may also become the target of DoS attacks. To achieve this, the attacker needs to recognize the firewall access control list, i.e., rule-set, and the order of rules inside this list. The attacker can then launch an attack by targeting rules at the bottom of this list. This makes the firewall busy with processing dummy requests, its performance degrades sharply, and it may go down. In this paper, a method to identify the order of the rules within the rule-set is presented. Then, a mechanism to make the sampling algorithm more efficient is described. We focus on discovering information related to the accept-rules only of a firewall's policy. Results show that a high level of precision and recall can be obtained for deducing the order of rules within a rule-set while requiring a very low cost.
机译:现在广泛使用防火墙来保护网络,并且它们也可能成为DOS攻击的目标。为此,攻击者需要识别防火墙访问控制列表,即规则集和此列表中规则的顺序。然后,攻击者可以通过在此列表底部定位规则来启动攻击。这使得防火墙忙于处理伪请求,其性能急剧下降,可能会下降。在本文中,提出了一种识别规则集内规则顺序的方法。然后,描述使采样算法更有效的机制。我们专注于发现与防火墙的政策有关的信息。结果表明,可以获得高水平的精度和召回,以便在需要非常低的成本的同时在规则集中推导规则集中的规则顺序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号